{"id":1989,"date":"2021-08-12T03:55:58","date_gmt":"2021-08-12T10:55:58","guid":{"rendered":"https:\/\/www.ssls.com\/blog\/?p=1989"},"modified":"2023-09-27T12:51:58","modified_gmt":"2023-09-27T19:51:58","slug":"amazon-web-services-has-shut-down-accounts-linked-to-pegasus-spyware","status":"publish","type":"post","link":"https:\/\/www.ssls.com\/blog\/amazon-web-services-has-shut-down-accounts-linked-to-pegasus-spyware\/","title":{"rendered":"Amazon Web Services has shut down accounts linked to Pegasus&nbsp;spyware"},"content":{"rendered":"\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.ssls.com\/blog\/wp-content\/uploads\/SSL_Blog_Amazon-Web-Services-bans-accounts-linked-with-Pegasus-spyware.png\" alt=\"\" class=\"wp-image-1895\"\/><\/figure>\n\n\n\n<p>Following investigations <a href=\"https:\/\/www.amnesty.org\/en\/latest\/research\/2021\/07\/forensic-methodology-report-how-to-catch-nso-groups-pegasus\/\">by Amnesty International<\/a> and <a href=\"https:\/\/www.theguardian.com\/news\/series\/pegasus-project\">The Pegasus Project<\/a> in mid-July, Amazon Web Services has banned all accounts and infrastructure linked to NSO Group, an Israeli surveillance vendor. These investigations laid bare some damning revelations and human rights implications concerning NSO\u2019s Pegasus software, a type of surveillance spyware that has been sold to governments around the world.&nbsp;<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">What happened?<\/h2>\n\n\n\n<p>In its report, Amnesty observed that the infected phone of a French human rights lawyer sent information to a server hosted by Amazon CloudFront. In a separate report, <a href=\"https:\/\/citizenlab.ca\/2021\/07\/amnesty-peer-review\/\">Citizen Lab<\/a> independently found that NSO had been using Amazon services extensively in 2021.<br><\/p>\n\n\n\n<p>Following these revelations, an <a href=\"https:\/\/www.vice.com\/en\/article\/xgx5bw\/amazon-aws-shuts-down-nso-group-infrastructure\">Amazon spokesperson told Vice<\/a> that it moved quickly to shut down all NSO infrastructure and accounts. This isn\u2019t the first time that Amazon services have <a href=\"https:\/\/www.vice.com\/en\/article\/qj4p3w\/nso-group-hack-fake-facebook-domain\">been linked to NSO<\/a>.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What\u2019s the big deal about Pegasus?<\/h2>\n\n\n\n<p>Considered one of the most powerful types of spyware ever developed, Pegasus can infiltrate smartphones with Android, iOS, Blackberry, and Symbian operating systems and essentially <a href=\"https:\/\/theconversation.com\/what-is-pegasus-a-cybersecurity-expert-explains-how-the-spyware-invades-phones-and-what-it-does-when-it-gets-in-165382\">turn them into 24\/7 surveillance devices<\/a>. Once a phone is infected, it can harvest any data from the device, from photos, text messages, and calls, as well as even filming and recording victims without them noticing.&nbsp;<br><\/p>\n\n\n\n<p>NSO claims that this software is only used for law enforcement and counterterrorism, not mass surveillance. However, there has been criticism of the vagueness of these terms. Indeed, Pegasus spyware has <a href=\"https:\/\/www.amnesty.org\/en\/latest\/news\/2021\/07\/world-leaders-potential-targets-of-nso-group-pegasus-spyware\/\">potentially targeted<\/a> a wide variety of people, from politicians and celebrities to activists, lawyers, government workers, and journalists. With \u201cterrorism\u201d being an elusive term at the best of times, it seems especially broad in this instance.&nbsp;<br><\/p>\n\n\n\n<p>In a statement regarding the revelations, Agnes Callamard, Amnesty International\u2019s Secretary General, said, \u201cNSO Group can no longer hide behind the claim that its spyware is only used to fight crime \u2013 it appears that Pegasus is also the spyware of choice for those wanting to snoop on foreign governments.\u201d The secretary went on to call for an international ban on selling this kind of surveillance equipment and software until a more robust human rights-compliant regulatory framework has been created to <a href=\"https:\/\/www.ssls.com\/blog\/duckduckgo-is-building-a-desktop-browser-that-respects-privacy\/\">protect<\/a> those at risk from unlawful cyber-surveillance.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Can I check if my phone has been infected?<\/h2>\n\n\n\n<p>If you\u2019re worried that your phone or device may have been compromised, <a href=\"https:\/\/www.theverge.com\/2021\/7\/21\/22587234\/amnesty-international-nso-pegasus-spyware-detection-tool-ios-android-guide-windows-mac\">Amnesty has released a tool<\/a> that you can use to check for any traces of Pegasus spyware. It\u2019s a little bit technical as it is command-line based, but not too complicated. The downside is that it\u2019s far more effective on Apple devices than Android. If you do have an Android device, you can still use the tool to check if your phone has any malicious SMS messages or APKs.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Wrap up<\/h2>\n\n\n\n<p>While it\u2019s promising that Amazon has suspended NSO accounts, this problem is far more significant than individual private companies keeping an eye out for potential abuse. As <a href=\"https:\/\/www.amnesty.org\/en\/latest\/news\/2021\/07\/pegasus-project-spyware-digital-surveillance-nso\/\">Amnesty has pointed out<\/a>, NSO is just one company in an industry that operates on the edges of international legality. To prevent similar or worse privacy violations from occurring in the future, there needs to be greater regulation over the cyber-surveillance industry as a whole.\n\n<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following investigations by Amnesty International and The Pegasus Project in mid-July, Amazon Web Services has banned all accounts and infrastructure linked to NSO Group, an Israeli surveillance vendor. These investigations laid bare some damning revelations and human rights implications concerning NSO\u2019s Pegasus software, a type of surveillance spyware that has been sold to governments around [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1989","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/1989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/comments?post=1989"}],"version-history":[{"count":3,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/1989\/revisions"}],"predecessor-version":[{"id":2578,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/posts\/1989\/revisions\/2578"}],"wp:attachment":[{"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/media?parent=1989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/categories?post=1989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ssls.com\/blog\/wp-json\/wp\/v2\/tags?post=1989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}